CVE-2025-5125: Howardehrenberg Custom Post Carousels With Owl

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it.

Affected products

  • Howardehrenberg Custom Post Carousels With Owl: before 1.4.12 (fixed in 1.4.12)

Published 2025-06-20. Last modified 2026-06-17.